Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
fortinet fortiportal vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv3
CVE-2022-43954
An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 up to and including 7.0.2 may allow a remote authenticated malicious user to read other devices' passwords in the audit log page.
Fortinet Fortiportal 7.0.2
Fortinet Fortiportal 7.0.1
Fortinet Fortiportal 7.0.0
4.3
CVSSv3
CVE-2024-21761
An improper authorization vulnerability [CWE-285] in FortiPortal version 7.2.0, and versions 7.0.6 and below reports may allow a user to download other organizations reports via modification in the request payload.
Fortinet Fortiportal 7.2.0
Fortinet Fortiportal
8.8
CVSSv3
CVE-2023-48791
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized commands vi...
Fortinet Fortiportal
Fortinet Fortiportal 7.2.0
7.8
CVSSv3
CVE-2021-26104
Multiple OS command injection (CWE-78) vulnerabilities in the command line interface of FortiManager 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x and 5.6.x, FortiAnalyzer 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x and 5.6.x, and FortiPo...
Fortinet Fortimanager
Fortinet Fortianalyzer
Fortinet Fortiportal
6.5
CVSSv3
CVE-2022-27490
A exposure of sensitive information to an unauthorized actor in Fortinet FortiManager version 6.0.0 up to and including 6.0.4, FortiAnalyzer version 6.0.0 up to and including 6.0.4, FortiPortal version 6.0.0 up to and including 6.0.9, 5.3.0 up to and including 5.3.8, 5.2.x, 5.1.0...
Fortinet Fortiportal
Fortinet Fortimanager
Fortinet Fortianalyzer
Fortinet Fortiswitch
6.5
CVSSv3
CVE-2021-36168
A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x prior to 6.0.5, FortiPortal 5.3.x prior to 5.3.6 and any FortiPortal prior to 6.2.5 allows authenticated malicious user to disclosure information via crafted GET...
Fortinet Fortiportal
8.1
CVSSv3
CVE-2021-36171
The use of a cryptographically weak pseudo-random number generator in the password reset feature of FortiPortal prior to 6.0.6 may allow a remote unauthenticated malicious user to predict parts of or the whole newly generated password within a given time frame.
Fortinet Fortiportal
8.1
CVSSv3
CVE-2021-36172
An improper restriction of XML external entity reference vulnerability in the parser of XML responses of FortiPortal prior to 6.0.6 may allow an attacker who controls the producer of XML reports consumed by FortiPortal to trigger a denial of service or read arbitrary files from t...
Fortinet Fortiportal
7.5
CVSSv3
CVE-2021-36174
A memory allocation with excessive size value vulnerability in the license verification function of FortiPortal prior to 6.0.6 may allow an malicious user to perform a denial of service attack via specially crafted license blobs.
Fortinet Fortiportal
6.1
CVSSv3
CVE-2021-36176
Multiple uncontrolled resource consumption vulnerabilities in the web interface of FortiPortal prior to 6.0.6 may allow a single low-privileged user to induce a denial of service via multiple HTTP requests.
Fortinet Fortiportal
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
administrator privileges
CVE-2024-1579
hardcoded
CVE-2023-20198
CVE-2024-33587
CVE-2024-33449
CVE-2024-4308
HTML injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »